We’re trying to tighten FileVault enforcement across our Mac fleet in Hexnode.
Some users enabled FileVault manually before we started managing it through Hexnode, so we changed the policy to allow those users to turn FileVault off manually and then let Hexnode enable it again with the managed configuration/key escrow.
A couple of things I want to confirm:
If a user disables FileVault manually, will Hexnode automatically re-enable it on the next restart or login?
Is there a period where the Mac remains unencrypted before Hexnode enforces the policy again?